OpenSSF/OSV advisory MAL-2026-17575 confirms this npm version as malicious. On require(), thunderboltRegistry.js runs an IIFE that shells out via child_process to collect host identity (`id`, `whoami`, `uname -a`), network interface listings (`ifconfig`/`ip addr`), and the contents of `/etc/hosts`, together with the machine hostname and a beacon containing Node version, platform, and pid. The collected output is sent via fetch to the hardcoded URL...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in css-kfvwax-polyfill (npm)
Details
On require(), thunderboltRegistry.js runs an IIFE that shells out via child_process to collect host identity (`id`, `whoami`, `uname -a`), network interface listings (`ifconfig`/`ip addr`), and the contents of `/etc/hosts`, together with the machine hostname and a beacon containing Node version, platform, and pid. The collected output is sent via fetch to the hardcoded URL https://unl9pgk6ei4uf80n5tf4iktspjvbuzkn9.oastify.com/ (Burp Collaborator OAST). The module also exports a Proxy mimicking Wix thunderbolt registry APIs (ensureComponentLoadersAreCreated, loadComponents, etc.) under namespaces such as thunderboltRegistry, siteAssetsRegistry, documentManagementRegistry, and editorRegistry, acting as a cover-story API shape consistent with a dependency-confusion or typosquat payload against Wix internal tooling. Installing or importing this package causes host reconnaissance data to be exfiltrated to attacker-controlled infrastructure.
Decision reason
OpenSSF Malicious Packages via OSV confirms css-kfvwax-polyfill@1.0.0 as malicious (MAL-2026-17575): Malicious code in css-kfvwax-polyfill (npm)